Skip to main content

crls

Creates, updates, deletes or gets a crl resource or lists crls in a region

Overview

Namecrls
TypeResource
DescriptionDefinition of AWS::RolesAnywhere::CRL Resource Type
Idawscc.rolesanywhere.crls

Fields

NameDatatypeDescription
crl_datastring
crl_idstring
enabledboolean
namestring
trust_anchor_arnstring
tagsarray
regionstringAWS region.

For more information, see AWS::RolesAnywhere::CRL.

Methods

NameResourceAccessible byRequired Params
create_resourcecrlsINSERTName, CrlData, region
delete_resourcecrlsDELETEIdentifier, region
update_resourcecrlsUPDATEIdentifier, PatchDocument, region
list_resourcescrls_list_onlySELECTregion
get_resourcecrlsSELECTIdentifier, region

SELECT examples

Gets all properties from an individual crl.

SELECT
region,
crl_data,
crl_id,
enabled,
name,
trust_anchor_arn,
tags
FROM awscc.rolesanywhere.crls
WHERE
region = 'us-east-1' AND
Identifier = '{{ crl_id }}';

INSERT example

Use the following StackQL query and manifest file to create a new crl resource, using stack-deploy.

/*+ create */
INSERT INTO awscc.rolesanywhere.crls (
CrlData,
Name,
region
)
SELECT
'{{ crl_data }}',
'{{ name }}',
'{{ region }}';

UPDATE example

Use the following StackQL query and manifest file to update a crl resource, using stack-deploy.

/*+ update */
UPDATE awscc.rolesanywhere.crls
SET PatchDocument = string('{{ {
"CrlData": crl_data,
"Enabled": enabled,
"Name": name,
"TrustAnchorArn": trust_anchor_arn,
"Tags": tags
} | generate_patch_document }}')
WHERE
region = '{{ region }}' AND
Identifier = '{{ crl_id }}';

DELETE example

/*+ delete */
DELETE FROM awscc.rolesanywhere.crls
WHERE
Identifier = '{{ crl_id }}' AND
region = 'us-east-1';

Permissions

To operate on the crls resource, the following permissions are required:

rolesanywhere:ImportCrl,
rolesanywhere:TagResource